Data retention
Customers define retention. The platform enforces it.
Every organisation has different purposes, duties and risks. YouRing lets customers define retention for operational data and limits technical data to the period required.
Last updated 24 August 2026
1. Principles
- Storage limitation: identifiable data is not kept for longer than necessary.
- Customer control: the controller defines periods for operational data.
- Minimisation: transient content and credentials expire automatically.
- Verifiable deletion: requests are applied to active systems and relevant providers.
- Limited exceptions: legal duties, abuse prevention, defence of rights and incident recovery.
2. Current periods and criteria
The periods below are the current technical reference. The contract, customer configuration or a legal duty may establish a shorter or longer period for operational data. Material changes will be reflected on this page.
| Category | Period or criterion |
|---|---|
| Account, organisation and permissions | For the contractual relationship and until offboarding or a valid customer instruction is completed. |
| Contacts, history, notes, tasks and callbacks | Defined by the customer according to purpose and legal basis. |
| Call metadata and recordings | Defined by the customer; a recording is kept only when the feature is enabled. |
| AI transcript and transient sensitive data | Usually up to 30 days in YouRing, unless a different contractual setting applies. |
| Context for an open AI task | Usually up to 90 days while continuity is needed; terminal context usually up to 30 days. |
| Technical mobile call events | Usually 30 days. |
| Sessions, refresh tokens and push tokens | Usually up to 90 days, with revocation on logout, expiry or device removal where applicable. |
| Temporary exports | Available for a current maximum of 6 hours. |
| Security logs and backups | A limited cycle based on operations, investigation, recovery and legal duties; copies expire through rotation. |
| Sales and support contacts | For as long as needed to respond, manage the relationship, comply with duties or defend rights. |
3. What the customer decides
The customer documents the purpose and legal ground for recordings, history, contacts, notes, integrations and AI. Retention is then agreed and applied in configuration or through operational instructions to YouRing.
A customer-defined period cannot override the law or justify indefinite retention without a purpose. YouRing may flag disproportionate settings and propose anonymisation, aggregation or shorter periods.
4. How deletion works
- Identity and authority are verified before execution.
- Deletion covers active records and associated storage objects within the approved scope.
- Tokens and access are revoked when an account or device is removed.
- Providers receive the applicable instruction where they hold a copy on our behalf.
- Protected backups are not used for normal operations and expire on their cycle; a restore reapplies pending deletions.
5. Exceptions and deletion holds
We may keep the minimum needed where required by law, a valid order, litigation, a security investigation or proof of compliance with an instruction. Access is restricted and data is deleted when the exception ends. Irreversibly anonymised data may be retained for statistics and operational improvement.
6. Service closure
At closure, the customer may request an export within the agreed format and period. We then delete or anonymise data under the customer's instruction, subject to legal duties and normal backup rotation.
Contact
Set or reduce a retention period
Identify the organisation, data category and requested period. We will confirm the impact and instruction before changing or deleting information.
Request a retention setting